Blocked that hard-coded google dns garbage.

  • jubilationtcornpone@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    2
    ·
    11 months ago

    I have a firewall rule to dst-nat any outgoing DNS requests not coming from piHole back to the piHole server. That way all devices on the LAN are forced to use piHole for DNS and can’t bypass it. I don’t have an OPNSense firewall but I would think it should be able to do that as well.

  • randombullet@feddit.de
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 months ago

    I do a DNS redirect on my Mikrotik router.

    It’s going to suck when DoH and DoT becomes more prevalent.

  • filister@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 months ago

    Hey man, can you share some resources that you followed to configure Opnsense as VM. I am in the same situation, bought a firewall, that I want to use as a hypervisor but didn’t configure yet the Opnsense and would love to educate myself more on the matter.

    • Pete90@feddit.de
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 months ago

      I’m currently using this guide to setup a OPNsense VM on proxmox. Home Network Guy also has an OPNsense guide, but for a full router.

      • filister@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        11 months ago

        Thanks for the link but in the series I can only find information about Pfsense and not Opnsense.

        • Pete90@feddit.de
          link
          fedilink
          English
          arrow-up
          0
          ·
          11 months ago

          It’s pretty similar, but I combined those two guides and that worked pretty well.

    • AdventuringAardvark@lemmy.oneOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      11 months ago

      No, you can block ads with a pihole. This is because Roku hard codes its dns server as 8.8.8.8. Pihole doesn’t handle IP addresses, only DNS.

      • Illiterate Domine@infosec.pub
        link
        fedilink
        English
        arrow-up
        0
        ·
        11 months ago

        Interesting. I set an adblocking dns via DHCP and, as far as I know, the Roku respects it. Ads are blocked and I can see it failing to delivery telemetry in my dns logs (most persistent thing on the network).

        I set a rule to catch outside dns to see if anything, the roku included, has been misbehaving.